Live opening · Posted 6 days ago

Senior Security Engineer, Offensive Security and Detection

Vancord · United States (Remote)
Linkedin Yes
You are 6 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 6 days ago
CompanyVancord
LocationUnited States (Remote)
Work modeYes
SourceLinkedin
Listed6 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
8 min from Linkedin publishing this role to us finding it
7 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
70,553 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

About the Job
Vancord is seeking an experienced Senior Security Engineer to work across our offensive and defensive security teams. This role sits on the Offensive Security team and reports to Offensive Security leadership. The majority of your day-to-day work will be penetration testing and engagement delivery, and a meaningful portion of your time will be spent inside our Security Operations Center building and validating the detections that catch the attacks you spend the rest of your week executing.
We are looking for someone who is deeply capable on the offensive side and genuinely interested in the defensive side, not someone who tolerates it. The value of this role comes from the feedback loop between the two. Techniques you use against client environments become detection content in Vancord's Vantage MDR service. Gaps you find in our detection coverage become priorities for the next round of testing. If you have ever finished a report and wished you could build the alert that would have caught you, this is that job.
About Vancord
Vancord provides managed services across infrastructure and security. As a senior member of the security engineering team, you will play a meaningful role across the project pipeline, from presales engineering and scoping through testing execution and final delivery of high-quality services and reports for both technical and executive audiences. You will also contribute directly to the detection engineering that protects our managed security clients.
How the Role Splits
Offensive work is the primary function and drives your schedule. Client engagements, scoping commitments, and report deadlines take precedence. Defensive work fills the remainder and is expected to be substantial rather than incidental, with dedicated capacity between engagements and during slower periods in the testing calendar. Expect the balance to shift week to week rather than following a fixed ratio.
Responsibilities
Offensive Security
Lead and perform in depth penetration tests across a wide range of digital infrastructures, including web applications and network systems, to identify and exploit vulnerabilities.
Own the end-to-end delivery of security engagements, including scoping, testing, and presentation of findings to clients.
Create detailed reports outlining methods used and the implications of findings, proposing actionable mitigation strategies tailored to both technical and executive audiences.
Evaluate and analyze results from security assessments of cloud infrastructure and services such as AWS, Azure, Microsoft 365, and Google Workspace.
Develop and refine playbooks, repeatable processes, and internal tooling to improve consistency, efficiency, and knowledge distribution across the team.
Contribute to presales engineering efforts, including scoping engagements and advising on testing approaches.
Stay current on penetration testing methodologies, tooling, and threat landscape developments, and translate them into refined testing strategies and expanded team capability.
Detection Engineering and Defensive Operations
Develop and tune detection content across Elastic Security, Microsoft Defender XDR, Microsoft Sentinel, and CrowdStrike Falcon, writing and maintaining correlation rules, analytics, and hunting queries in KQL, ES|QL, EQL, and equivalent query languages.
Map detection coverage against MITRE ATT&CK, identify gaps, and help drive the roadmap to close them.
Improve signal to noise through systematic tuning, suppression logic, and enrichment rather than ad hoc fixes, and document the reasoning so analysts understand what a rule catches, what it misses, and why it fires.
Build automation workflows in Vancord's SOAR platform to accelerate triage, enrichment, and response, reducing analyst manual workload and mean time to respond.
Conduct structured threat hunts across the managed customer fleet, informed by current adversary tradecraft and your own offensive experience.
Serve as a senior technical resource during complex investigations and high severity incidents, contributing attacker perspective to scoping, containment, and root cause analysis.
Support ECS aligned telemetry pipelines and normalization workflows so that detections operate on consistent, high-fidelity data across a multi-tenant environment.
Keep detection content consistent across the platforms Vancord operates, contributing to detection-as-code practices as they mature, so a detection built for one customer platform reaches the rest of the fleet.
Cross Team Work
Translate techniques observed or executed during offensive engagements into concrete detection requirements, test cases, and coverage improvements.
Run adversary emulation and detection validation exercises against Vancord's own detection stack, then work with the SOC to close what does not fire.
Provide feedback to Product and Engineering to improve Vantage MDR, particularly on detection content and coverage.
Bring defensive telemetry insight back into offensive engagements, helping clients understand not just what was exploitable but what their monitoring would and would not have caught.
Client Engagement and Mentorship
Interface with clients and staff with professionalism and a positive attitude, serving as a trusted advisor on security matters.
Provide guidance, mentorship, and technical oversight to members of Vancord and our partner teams across both offensive and defensive disciplines.
Communicate findings, detection coverage, and remediation guidance clearly to audiences ranging from system administrators to executive leadership.
Partner with the strategic consulting and customer success teams to ensure client needs are met and exceeded.
Required Qualifications
Significant experience in cybersecurity with a strong emphasis on penetration testing. We are interested in skillset and expertise, not longevity in the field.
A proven track record of independently leading penetration testing engagements and delivering valuable, actionable insights to clients.
Hands on experience writing and tuning detection logic in a SIEM or EDR query language such as KQL, ES|QL, or EQL. Candidates should be able to walk through a detection they wrote, what it catches, what it misses, and how they tuned it.
Working knowledge of SIEM, EDR, and SOAR platforms and of security telemetry generally, including tools such as Elastic, Sentinel, Defender, CrowdStrike, or SentinelOne.
Proficiency in scripting and programming with Python, Bash, and PowerShell for automation, custom tooling, or exploit development.
Deep experience with Windows and Linux or Unix operating systems, including advanced command line proficiency.
Practical familiarity with MITRE ATT&CK as a working framework rather than a reference document.
Ability to take an attacker technique, describe the observable artifacts it leaves behind, and explain how you would detect it and confirm the detection works. This is the bridge between the two halves of the role.
Excellent communication and technical writing skills, with the ability to convey complex findings to diverse audiences.
Strong problem-solving skills, attention to detail, and the ability to manage multiple engagements simultaneously.
A track record of self-education, continuous improvement, and adaptability to evolving threats and technologies.
Remote candidates must have a stable internet connection and a dedicated workspace for customer and internal meetings. Candidates will be expected to appear on camera during these meetings.
Preferred Qualifications
Relevant offensive security certifications such as OSCP, OSCE, OSWE, GPEN, GXPN, CRTO, HTB CPTS, or similar advanced credentials.
Direct experience with red team operations, adversary simulation, or purple team engagements.
Detection as code experience, including version-controlled detection content, peer review of detection logic, CI/CD promotion pipelines, and automated testing of rules before production deployment.
Experience building SOC automation through SOAR platforms and Python based tooling, including enrichment pipelines, ETL workflows, and data stream integrations.
Experience developing threat intelligence driven detections or leading structured hunts.
Experience supporting incident response engagements, including containment decisions and executive communication under pressure.
Background in software development at any scale.
Background managing server infrastructure, designing or deploying campus sized networks, or managing cloud infrastructure.
Experience in an MSSP or MDR environment, including multi-tenant operations.
Experience with presales, client facing consulting, or engagement scoping.
Familiarity with SOC 2, ISO, NIST, CMMC, or HIPAA frameworks as they apply to client environments.

Work arrangement
Yes

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App